Bug 804392 (CVE-2013-0292) - VUL-1: CVE-2013-0292: dbus-1-glib: DBUS signal spoofing
Summary: VUL-1: CVE-2013-0292: dbus-1-glib: DBUS signal spoofing
Status: RESOLVED FIXED
Alias: CVE-2013-0292
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Fridrich Strba
QA Contact: Security Team bot
URL:
Whiteboard: maint:planned:update
Keywords:
Depends on:
Blocks:
 
Reported: 2013-02-19 10:22 UTC by Sebastian Krahmer
Modified: 2016-01-04 12:29 UTC (History)
6 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Dominique Leuenberger 2013-02-19 11:01:26 UTC
Update for Factory prepared and submitted to the devel project:

Request: #155799

  submit:       home:dimstar:branches:Base:System/dbus-1-glib(cleanup) -> Base:System


Message:
- Update to version 0.100.1:
  + dbus-gproxy: Verify sender of NameOwnerChanged signals to be
    o.f.DBus (CVE-2013-0292, bnc#804392).
  + Some cleanups.
  + Other bugs fixed: fdo#23633, fdo#40711, fdo#55729, fdo#55730.

State:   new        2013-02-19T11:00:33 dimstar
Comment: <no comment>
Comment 2 Bernhard Wiedemann 2013-02-19 12:02:00 UTC
This is an autogenerated message for OBS integration:
This bug (804392) was mentioned in
https://build.opensuse.org/request/show/155800 Factory / dbus-1-glib
Comment 3 Swamp Workflow Management 2013-02-19 23:00:14 UTC
bugbot adjusting priority
Comment 4 Sebastian Krahmer 2013-04-22 08:50:39 UTC
can be closed then
Comment 6 Marcus Meissner 2013-05-31 14:24:38 UTC
as the glib bindings are used by some packages, we need this fix also for the SLE 11 and perhaps also the SLE 10 codebases.

(again, it depends on a using package for this problem to be effective)
Comment 10 Victor Pereira 2016-01-04 12:29:05 UTC
We are not aware of packages that rely on dbus signals (via dbus-glib)
for authentication